Skip to content

Notation with internal certificate authority #1103

Answered by akashsinghal
olopost asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @olopost,

Thanks for reaching out. Here's a few questions to get started for us to be able to diagnose the issue:

  1. Are you using the open-source version of Ratify or managed version of Ratify through a cloud provider?
  2. Could you paste the Constraint Template used? You can find this as a resource of type ConstraintTemplate in the templates.gatekeeper.sh definition group.
  3. From the error it looks like you might have 2 signatures attached to the image. The failure is likely caused by the extra signature's cert not matching. The notation CLI looks for all signatures attached to the image and returns a successful response if at least one of them is successful. However, Ratify leaves the behav…

Replies: 4 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by olopost
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants